AI security report 2026: what Canadian business owners face
This report collects the AI security and AI cybersecurity numbers that matter to the owner of a Canadian business with $5M to $50M in revenue that makes, moves or sells goods. Every figure links to its primary source and carries its date. Canadian sources come first: Statistics Canada, the Canadian Centre for Cyber Security, the Canadian Anti-Fraud Centre and the privacy regulators. Global studies fill the gaps and are labelled global.

Key findings
Each finding gives one number, what it measures, its source and its date. Findings from studies outside Canada are marked global.
- In the second quarter of 2026, 19.2% of Canadian businesses said they had used AI to produce goods or deliver services in the previous 12 months, according to Statistics Canada (June 11, 2026).
- 32.8% of Canadian businesses with 20 to 99 employees plan to use AI to produce goods or deliver services over the next 12 months, according to Statistics Canada’s survey for the third quarter of 2026 (October 1, 2026).
- 35.9% of Canadian workers aged 15 to 69 used generative AI tools at work in the 12 months to March 2026, according to Statistics Canada (July 30, 2026).
- 22.3% of Canadian businesses with 20 to 99 employees named cybersecurity or privacy concerns as a barrier that limits their use of AI, according to Statistics Canada data for the second quarter of 2026 (May 27, 2026).
- Half (50%) of the 503 Canadian organizations in the 2026 CIRA Cybersecurity Survey said they have an AI policy (October 2, 2026).
- 67% of users who accessed AI platforms from corporate devices did so with non-corporate accounts, a form of shadow AI, according to Verizon’s 2026 Data Breach Investigations Report (global, May 19, 2026).
- 43% of the breached organizations in IBM’s 2026 Cost of a Data Breach study reported security incidents involving unapproved AI use, according to IBM (global, September 15, 2026).
- 28% of Canadian organizations in IBM’s 2026 Cost of a Data Breach study reported an AI-generated attack, according to IBM Canada (July 29, 2026).
- 23.1% of Canadian businesses with 50 to 249 employees were impacted by cyber security incidents in 2023, according to Statistics Canada (October 21, 2024).
- Canadian businesses with 10 or more employees spent $1.2 billion recovering from cyber security incidents in 2023, according to Statistics Canada (October 21, 2024).
- The average cost of a data breach at the Canadian organizations in IBM’s 2026 Cost of a Data Breach study was CA$7.11 million, the highest since the study began, according to IBM Canada (July 29, 2026).
- Spear phishing fraud losses in Canada were more than $68 million in 2025, according to the Canadian Anti-Fraud Centre (May 13, 2026); this fraud includes emails that pose as a supplier and ask for payment to a new bank account.
AI adoption and the worries holding owners back
AI use by Canadian businesses has tripled in two years. Statistics Canada’s Canadian Survey on Business Conditions asked about it in the second quarter of 2026. That quarter, 19.2% of businesses said they had used AI to produce goods or deliver services in the previous 12 months. The share was 12.2% a year earlier and 6.1% in the second quarter of 2024.
Plans grew fastest among larger businesses. In the third quarter of 2026, 32.8% of businesses with 20 to 99 employees planned to use AI over the next 12 months, up from 15.0% a year earlier.
| Business size | Used AI in the past 12 months, Q2 2026 | Plan to use AI in the next 12 months, Q3 2026 |
|---|---|---|
| 1 to 4 employees | 19.9% | 25.6% |
| 5 to 19 employees | 14.9% | 21.0% |
| 20 to 99 employees | 25.8% | 32.8% |
| 100 or more employees | 27.8% | 37.5% |
| All businesses | 19.2% | 25.2% |
Sources: Statistics Canada, Table 33-10-1167-01 (May 27, 2026) and its analysis of planned AI use (October 1, 2026).
Manufacturers, wholesalers and transport companies use AI less than the average business. Manufacturing stands out in plans: 24.4% of manufacturers planned to use AI in the next 12 months, close to the all-industry rate of 25.2%.
| Industry | Used AI, Q2 2026 | Plan to use AI, Q3 2026 | Named cybersecurity or privacy concerns as a barrier, Q2 2026 |
|---|---|---|---|
| Manufacturing | 13.1% | 24.4% | 9.2% |
| Wholesale trade | 7.9% | 16.8% | 12.7% |
| Retail trade | 19.2% | 16.0% | 13.6% |
| Transportation and warehousing | 9.8% | 8.0% | 6.7% |
| All industries | 19.2% | 25.2% | 13.4% |
Sources: Statistics Canada, Table 33-10-1167-01, Table 33-10-1169-01 (both May 27, 2026) and the analysis of planned AI use (October 1, 2026).
Cybersecurity and privacy are the barrier named most often
Statistics Canada asked businesses in the second quarter of 2026 what limits their use of AI. Cybersecurity or privacy concerns came first, named by 13.4% of businesses, ahead of cost at 10.6%. The concern rises with size. Among businesses with 20 to 99 employees, 22.3% named it, against 15.1% who named cost.
| Business size | Named cybersecurity or privacy concerns as a barrier to AI use, Q2 2026 |
|---|---|
| 1 to 4 employees | 11.6% |
| 5 to 19 employees | 12.2% |
| 20 to 99 employees | 22.3% |
| 100 or more employees | 30.0% |
| All businesses | 13.4% |
Source: Statistics Canada, Table 33-10-1169-01 (May 27, 2026). Each bar is drawn to the share of all businesses of that size.
More than a third of workers use generative AI at work
Statistics Canada also asked workers. In March 2026, 35.9% of workers aged 15 to 69 had used generative AI tools at work in the previous 12 months. Of those users, 31.4% used them daily. Among workers who had not used them, 9.8% cited security, privacy, environmental or ethical concerns. Only 5.0% of non-users said a company or organizational policy limited their use. The worker survey and the business survey ask different questions, so their rates are not directly comparable.
Half of the organizations CIRA surveyed have an AI policy
The 2026 CIRA Cybersecurity Survey asked 503 cybersecurity decision-makers at Canadian organizations with at least 50 computer-using employees. Private sector organizations in the sample have no more than 999 employees, and 70% of respondents reported annual revenue between $1M and $100M.
| Measure | Share of organizations, 2026 |
|---|---|
| Have integrated AI tools into workflows and operations | 66% |
| Worried about cyber threats from AI tools or AI-enabled attacks | 82% |
| Have an AI policy | 50% |
| Developing an AI policy | 36% |
| No plan for an AI policy | 12% |
Source: CIRA, 2026 Cybersecurity Survey report (October 2, 2026), survey conducted by The Strategic Counsel in June and July 2026. Among respondents worried about AI threats, the leading concerns were data gathered by AI tools (67%), improved phishing emails and texts (60%), deepfake images and videos (49%), and deepfake voices (37%).
What AI changes for attackers
The Canadian Centre for Cyber Security (the Cyber Centre) judges that AI is almost certainly lowering the barriers to entry for attackers and improving the quality, scale and precision of their attacks. That judgment is in its National Cyber Threat Assessment 2025-2026, published October 30, 2024. In a June 24, 2026 statement, the Cyber Centre said threat actors already use AI to make phishing, voice scams and deepfake impersonation more convincing, faster and at greater scale.
IBM’s 2026 Cost of a Data Breach study found that one in four malicious breaches was AI-enabled, a 56% increase over the previous year (global, July 29, 2026). Those breaches cost an average of US$6 million, and most came from deepfake impersonation and AI-enabled malware. In Canada, 28% of the organizations in the same study reported an AI-generated attack.
Phishing that reads like your supplier wrote it
The Cyber Centre’s threat assessment says attackers use AI to write personalized phishing emails at scale, in grammatically correct language that mimics human writing styles. That makes phishing harder for people and filters to spot.
Attackers are also moving to the phone. Verizon’s 2026 Data Breach Investigations Report found that social engineering by fake text messages and voice calls succeeded 40% more often than email phishing (global, May 19, 2026).
Cloned voices and deepfake video
Voice cloning uses AI and short audio samples to imitate a person’s voice, according to the Cyber Centre’s guidance on voice phishing (July 2026). In June 2025, the Cyber Centre and the Canadian Anti-Fraud Centre (CAFC) warned of a campaign aimed at business executives and senior public officials. Some of its calls used AI to mimic the voices of senior government officials.
The Cyber Centre’s social engineering guidance sets the rule for owners: “Audio or video alone should not be considered proof of identity, especially for sensitive or unusual requests.” It says to confirm any request involving a sensitive action through a second, independent form of communication.
Invoice and payment redirection fraud
The CAFC describes spear phishing attacks that begin once fraudsters have identified an accounts payable employee. The fraudsters study a company’s language patterns, payment schedules and key contacts. Then they pose as a supplier or contractor and ask for payment of an invoice to a new bank account.
Spear phishing losses in Canada were more than $68 million in 2025, and nearly $31 million in the first three months of 2026, according to the CAFC (May 13, 2026). The CAFC says these payment redirection frauds commonly target small and medium enterprises. Across all fraud types, Canadians lost over $704 million in 2025, and the CAFC says only 5% to 10% of frauds are reported.
Faster attacks on what faces the internet
Frontier AI models, the most capable models available, can help attackers find and exploit weaknesses much faster than before, the Cyber Centre’s June 2026 statement says. That shortens the time defenders have to respond, in some cases from days or weeks to hours.
Verizon’s 2026 report found that exploiting a software vulnerability was the most common way into a breach for the first time in the report’s 19 editions, at 31% of breaches (global). Manufacturing shows the same pattern.
| Manufacturing breaches, 2026 report | Figure |
|---|---|
| Incidents studied | 3,627, of which 2,713 had confirmed data disclosure |
| Breaches that started with exploitation of a vulnerability | 38% |
| Breaches that started with phishing | 13% |
| Breaches involving ransomware | 61% |
| Breaches involving a third party, such as a supplier or IT provider | 61% |
Source: Verizon, 2026 DBIR Manufacturing snapshot (global, May 19, 2026).
Company data leaking into public AI tools
Shadow AI means staff using AI tools that the company has not approved, often on personal accounts. The Cyber Centre’s June 2026 statement lists unapproved use of AI tools and exposure of sensitive data among the risks AI brings from inside an organization. Its generative AI guidance warns that users may unknowingly put sensitive corporate data or personal information into their prompts (December 2025).
We found no Canadian source that measures shadow AI directly, so the figures below come from two global studies.
| Measure | Figure | Source |
|---|---|---|
| Employees who use AI on corporate devices at least once every 15 days | 45%, up from 15% a year earlier | Verizon DBIR 2026 |
| Users who accessed AI platforms from corporate devices with non-corporate accounts | 67% | Verizon DBIR 2026 |
| Users with unauthorized AI browser extensions, at the average company | More than 15% | Verizon DBIR 2026 |
| Breached organizations that reported security incidents involving unapproved AI use | 43%, up from 20% a year earlier | IBM, 2026 |
| Share of those incidents that led to data loss or compromise | 49% | IBM, 2026 |
| Organizations with an AI-related breach that lacked proper AI access controls | 92% | IBM, 2026 |
Sources: Verizon, 2026 Data Breach Investigations Report (May 19, 2026). IBM, article on the 2026 study (September 15, 2026) and X-Force analysis (July 29, 2026). All figures are global.
Verizon found that source code was the type of data most often submitted to external AI models, followed by images and other structured data. In 3.2% of data loss prevention events, research and technical documentation was uploaded to untrusted, unauthorized AI systems. For a manufacturer, that category would include drawings and specifications.
How often Canadian businesses are hit, and what it costs
Statistics Canada’s Canadian Survey of Cyber Security and Cybercrime is the official measure. Its latest published results cover 2023 and were released on October 21, 2024. That year, 16.1% of businesses with 10 or more employees were impacted by cyber security incidents, down from 20.8% in 2019. The share was lower for every size in 2023, and larger businesses were still hit more often.
| Business size | 2019 | 2021 | 2023 |
|---|---|---|---|
| Small, 10 to 49 employees | 18.4% | 16.2% | 14.3% |
| Medium, 50 to 249 employees | 29.3% | 25.1% | 23.1% |
| Large, 250 or more employees | 43.5% | 36.5% | 29.9% |
| All businesses | 20.8% | 18.1% | 16.1% |
Source: Statistics Canada, Table 22-10-0076-01 (October 21, 2024). Share of businesses impacted by cyber security incidents in each year.
Wholesalers and manufacturers were hit more often than the average business in 2023.
| Industry | Businesses impacted by cyber security incidents, 2023 |
|---|---|
| Wholesale trade | 20.9% |
| Manufacturing | 19.2% |
| Transportation and warehousing | 16.7% |
| Retail trade | 14.2% |
| All businesses | 16.1% |
Source: Statistics Canada, Table 22-10-0076-01 (October 21, 2024). Businesses with 10 or more employees. Each bar is drawn to the share of all businesses in that industry.
Scams and fraud were the most common method, used against 50% of impacted businesses. Ransomware hit 13% of impacted businesses, and 88% of its victims did not pay. Only 26% of businesses had written cyber security policies, the same share as in 2021, and 22% gave non-IT staff formal cyber security training. Half had cyber security employees. The most common reason for having none was using consultants or contractors instead, at 47%.
The 2026 CIRA survey gives a more recent view of ransomware. Of the organizations surveyed, 21% had been victims of a successful ransomware attack in the previous 12 months. Of those victims, 75% paid the ransom.
What incidents and fraud cost
| Measure | Figure | Scope and source |
|---|---|---|
| Spending to recover from cyber security incidents, 2023 | $1.2 billion, double the 2021 total | Canada, businesses with 10 or more employees. Statistics Canada, October 21, 2024 |
| Average cost of a data breach | CA$7.11 million | Canadian organizations in a global study. IBM Canada, July 29, 2026 |
| Average cost of a data breach at industrial organizations | CA$8.89 million | Canadian organizations in a global study. IBM Canada, July 29, 2026 |
| Average cost of a data breach | US$4.99 million | Global. IBM, July 29, 2026 |
| Average cost of an AI-enabled malicious breach | US$6 million | Global. IBM, July 29, 2026 |
| Fraud losses reported, all types, 2025 | Over $704 million | Canada. CAFC, March 6, 2026 |
| Spear phishing fraud losses, 2025 | More than $68 million | Canada. CAFC, May 13, 2026 |
IBM’s averages describe the breached organizations in its study, which numbered 602 worldwide. They are not an estimate for a business of a given size. Statistics Canada’s survey is the better guide to how often a business of your size is hit. IBM also found that supply-chain compromise was the largest factor adding to breach costs in Canada, at about CA$367,899 per breach.
What the law asks of a Canadian business using AI on personal information
Canada’s federal, provincial and territorial privacy commissioners say generative AI does not sit outside existing privacy law. Their principles for generative AI (December 7, 2023) state that organizations using it must comply with the privacy laws that already apply. This section summarizes what the federal regulator and Quebec’s regulator ask. It is not legal advice, so ask a lawyer about your own obligations.
Federal law: PIPEDA
The Personal Information Protection and Electronic Documents Act (PIPEDA) applies to private-sector organizations across Canada that collect, use or disclose personal information in the course of a commercial activity. Alberta, British Columbia and Quebec have their own private-sector laws, deemed substantially similar, which generally apply within those provinces.
Under PIPEDA, a business must report to the Office of the Privacy Commissioner of Canada (OPC) any breach of security safeguards involving personal information that poses a real risk of significant harm. It must notify the people affected as soon as feasible. It must also keep a record of every breach for two years, whether or not the breach is reportable. Knowingly breaking these rules is an offence that could lead to fines.
For organizations that use generative AI, the commissioners’ principles include these points:
- Use anonymized or de-identified information in prompts where possible, rather than personal information.
- Enter personal information, especially sensitive or confidential information, into a prompt only where authorized.
- Unless otherwise required, do not retain prompts, use them for secondary purposes or disclose them.
- Accountability for a decision rests with the organization, not with the AI system that supported it.
In 2025-2026, businesses filed 696 breach reports with the OPC, which says they affected more than 20 million Canadians. According to the OPC’s annual report (June 4, 2026), unauthorized access accounted for 78% of those reports. More than two-thirds of the unauthorized access cases (68%) came from a cybersecurity incident. Social engineering caused 13% and employees misusing their access caused 8%.
Not every business keeps the breach records the law requires. In the OPC’s 2025-2026 survey of 800 businesses that sell to consumers, 81% said they keep records of all data breaches involving customers’ personal information. Another 9% said they do not (May 29, 2026). The same survey found that 16% used AI in their operations and 65% used multi-factor authentication to protect customer information.
Quebec: Law 25
Quebec’s private-sector privacy law, as amended by Law 25, is enforced by the Commission d’accès à l’information (CAI). The CAI’s guidance for businesses, in French, sets out these duties:
- A person in charge. The person with the highest authority in the business, such as its chief executive, is responsible by default for protecting personal information. The role can be delegated in writing, and the person’s title and contact information must be published on the business’s website.
- Privacy impact assessments. A business must carry out a privacy impact assessment for any project to acquire, develop or overhaul an information system or electronic service delivery that involves personal information. It must also do one before communicating personal information outside Quebec.
- Service providers outside Quebec. The same assessment applies before a business entrusts a person or body outside Quebec with collecting, using, communicating or keeping personal information on its behalf. The communication must always be covered by a written agreement. If an AI vendor would process personal information for you outside Quebec, check this rule with your lawyer.
- Confidentiality incidents. A business must notify the CAI and the people concerned of an incident that presents a risk of serious injury. It must record every incident in a register, kept for at least five years.
- Automated decisions. When a decision about a person is based exclusively on automated processing of their personal information, the business must tell them, at the latest when it informs them of the decision. On request, it must explain the information and main factors used, and let them submit observations to a staff member who can review the decision.
- Penalties. The CAI can impose administrative monetary penalties that could reach $10 million or 2% of worldwide turnover.
Ten controls for a $5M to $50M business
These ten controls draw on the Cyber Centre’s June 2026 statement, its top 10 AI security actions (May 2026), the CAFC’s advice on payment fraud and the privacy rules above. Each one ends with a test for when it is done.
- Approve one AI tool for company work. Choose a business plan whose terms keep your data out of model training, which the Cyber Centre calls “no train” defaults. Secure AI at work covers which account to use and what to switch off. Done when every employee knows which tool is approved.
- Write a one-page AI policy. Name the approved tools, the records that never go into a public tool, such as customer personal information, drawings and prices, and who approves exceptions. The AI policy template gives you a start. Done when every employee has read and signed it.
- Find the shadow AI already in use. The Cyber Centre’s top 10 actions say to map the sanctioned and unsanctioned AI models on your network. Ask each team which AI tools and browser extensions it uses, and check sign-in and firewall logs. Shadow AI covers how. Done when you have a list.
- Turn on phishing-resistant multi-factor authentication. The Cyber Centre recommends it in its June 2026 statement. Start with email, banking, finance and administrator accounts. Done when a stolen password alone cannot open any of them.
- Put a call-back rule on payment and banking changes. No change to a supplier’s banking details, and no urgent transfer, until someone confirms it on a phone number already on file. The CAFC recommends confirming banking changes through trusted contact information. Done when the rule is written into your payment procedure.
- Patch what faces the internet first. Apply security patches promptly, reduce what is exposed to the internet, and replace unsupported systems, as the Cyber Centre’s June 2026 statement advises. AI cybersecurity covers the attacks this blocks. Done when nothing reachable from the internet runs unsupported software.
- Limit what each AI tool can reach. Connect AI to company systems with the permissions of the person asking, read-only where possible, and log what it accessed. The Cyber Centre says to reduce AI models’ access to private data. If some records must stay under your control, see private AI for business. Done when no AI tool holds an administrator account.
- Keep a person on every action that pays, ships or sends. The Cyber Centre’s top 10 actions call for human checkpoints in automated workflows. The privacy commissioners add that accountability for a decision stays with the organization. Done when no AI tool can complete a payment, an order or an outside email on its own.
- Get your AI vendor’s data terms in writing. The Cyber Centre says AI vendor contracts should prohibit unauthorized use of your data for training and include audit rights and liability terms. Find out where prompts and files are processed and stored, and for how long. In Quebec, do the privacy impact assessment and sign a written agreement before personal information leaves the province. Done when the answers are in the contract.
- Keep offline backups, a tested incident plan and a breach register. The Cyber Centre says to test incident response plans and plan for containment and recovery. Keep the breach records that PIPEDA requires for two years and Quebec requires for five. Done when you have restored from a backup and run the plan once this year.
Check your setup against the ten controls
Tell Derik which AI tools your team uses and what they connect to. He will tell you which of the ten controls your setup already covers and which to add first.
Start a conversationMethodology and sources
This report includes statistics on AI use, AI-related security risk, cyber incidents, fraud and privacy breaches that bear on Canadian businesses. Each one was taken from the publisher’s own report, page or data table and checked against that source on October 5, 2026. The statistics were published between October 21, 2024 and October 2, 2026. The legal guidance includes the privacy commissioners’ principles for generative AI from December 7, 2023. Where a source has several editions, the report uses the latest one published.
- Canadian first. Canadian figures and guidance come from Statistics Canada, the Cyber Centre, the CAFC, the OPC, the CAI and CIRA. IBM’s Canadian figures come from the Canadian results of its global study and are labelled as such.
- Global where Canada has no data. Shadow AI, AI-enabled breaches and manufacturing breach patterns come from IBM’s 2026 Cost of a Data Breach study, based on 602 organizations breached between March 2025 and February 2026, and Verizon’s 2026 Data Breach Investigations Report, based on more than 22,000 confirmed breaches in 145 countries. These figures are marked global.
- Survey scope. Statistics Canada’s business conditions survey covers businesses with employees and was collected from April 1 to May 6, 2026, and from July 2 to August 6, 2026. Its cyber security survey covers enterprises with 10 or more employees and was collected from January to March 2024 for the year 2023. The worker figures come from a supplement to the Labour Force Survey of March 2026. CIRA surveyed 503 decision-makers in June and July 2026. The OPC surveyed 800 businesses that sell to consumers from January 19 to February 25, 2026.
- Quality. Statistics Canada rates the quality of each estimate with a letter from A to F. Every Statistics Canada estimate in this report’s tables is rated A or B, the two highest grades.
- Fraud figures. CAFC figures count losses reported to the CAFC. The CAFC says these losses represent only a fraction of the harm, because only 5% to 10% of frauds are reported.
- Next edition. Statistics Canada collected its 2025 Canadian Survey of Cyber Security and Cybercrime from January 14 to March 31, 2026. This report is updated each year at the same address, and will use those results once they are published.
| Source | Publisher | Date | Scope |
|---|---|---|---|
| Analysis on AI use by businesses, Q2 2026 | Statistics Canada | June 11, 2026 | Canada |
| Tables 33-10-1167-01 and 33-10-1169-01 | Statistics Canada | May 27, 2026 | Canada |
| Analysis on planned use of AI, Q3 2026 | Statistics Canada | October 1, 2026 | Canada |
| Generative AI use among Canadian workers, March 2026 | Statistics Canada | July 30, 2026 | Canada |
| Impact of cybercrime on Canadian businesses, 2023, and Table 22-10-0076-01 | Statistics Canada | October 21, 2024 | Canada |
| National Cyber Threat Assessment 2025-2026 | Canadian Centre for Cyber Security | October 30, 2024 | Canada |
| Statement on frontier AI models | Canadian Centre for Cyber Security | June 24, 2026 | Canada |
| Top 10 AI security actions (ITSAP.10.049) | Canadian Centre for Cyber Security | May 2026 | Canada |
| Generative AI (ITSAP.00.041) | Canadian Centre for Cyber Security | December 2025 | Canada |
| Social engineering (ITSAP.00.166) and voice phishing (ITSAP.00.102) | Canadian Centre for Cyber Security | July 2026 | Canada |
| Fraud Prevention Month release and payment redirection release | Canadian Anti-Fraud Centre | March 6 and May 13, 2026 | Canada |
| Annual report 2025-2026 | Office of the Privacy Commissioner of Canada | June 4, 2026 | Canada |
| 2025-2026 survey of Canadian businesses on privacy | Office of the Privacy Commissioner of Canada | May 29, 2026 | Canada |
| Principles for generative AI | Federal, provincial and territorial privacy commissioners | December 7, 2023 | Canada |
| Main changes under Law 25, in French | Commission d’accès à l’information | Consulted October 5, 2026 | Quebec |
| 2026 CIRA Cybersecurity Survey | CIRA | October 2, 2026 | Canada |
| Cost of a Data Breach 2026, Canadian results | IBM | July 29, 2026 | Canada, from a global study |
| Cost of a Data Breach 2026 | IBM | July 29, 2026 | Global |
| 2026 Data Breach Investigations Report | Verizon | May 19, 2026 | Global |
The photo is by Hyundai Motor Group on Unsplash, used under the Unsplash License.
How to cite this report
Lawlis, D. (2026, October 5). AI security report 2026: What Canadian business owners face. ThriveAI. https://thriveai.com/ai-security-report/
You may reuse the key findings and tables in this report under the Creative Commons Attribution 4.0 International licence (CC BY 4.0), with a link back to this page. The licence covers ThriveAI’s own compilation only. It does not cover text quoted from other publishers, which stays under its publisher’s terms. When you reuse a figure, cite its original source as well.
How ThriveAI helps
ThriveAI is an AI engineering company in Ottawa that builds private AI systems on a company’s own data, for businesses that make, move or sell physical goods. From the checklist above, ThriveAI builds the approved AI tool: one your staff can use with drawings, prices and customer lists, connected to your ERP with read-only access. A named person approves every action. Security software and monitoring stay with your IT provider.
The platform is designed to keep each client’s data on its own server in Canada. You choose the model that reads it: one running on that server, or a hosted model under a written zero data retention agreement, in which the provider agrees to keep none of your requests after answering. A hosted model may process requests outside Canada. Derik Lawlis, the founder, leads every project. More on the company is on the About page.